#VU104008 Buffer overflow in Intel products - CVE-2024-31155
Published: February 17, 2025
Vulnerability identifier: #VU104008
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-31155
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
UEFI firmware
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
UEFI firmware
4th Generation Intel Xeon Scalable Processors
5th Generation Intel Xeon Scalable processors
Intel Xeon W2400 processor
Intel Xeon W3400 Processor
Software vendor:
Intel
Intel
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the UEFI firmware. A local administrator can trigger memory corruption and execute arbitrary code on the target system with elevated privileges.
Remediation
Install updates from vendor's website.